6
CVSSv2

CVE-2014-3037

Published: 10/09/2014 Updated: 29/08/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in IBM Configuration Management Application (aka VVC) in IBM Rational Engineering Lifecycle Manager prior to 4.0.7 and 5.x prior to 5.0.1, Rational Software Architect Design Manager prior to 4.0.7 and 5.x prior to 5.0.1, and Rational Rhapsody Design Manager prior to 4.0.7 and 5.x prior to 5.0.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm rational rhapsody design manager 3.0

ibm rational rhapsody design manager 3.0.0.1

ibm rational rhapsody design manager 4.0.5

ibm rational rhapsody design manager 3.0.1

ibm rational rhapsody design manager 4.0

ibm rational rhapsody design manager 5.0

ibm rational rhapsody design manager 4.0.1

ibm rational rhapsody design manager 4.0.2

ibm rational rhapsody design manager

ibm rational rhapsody design manager 4.0.3

ibm rational rhapsody design manager 4.0.4

ibm rational engineering lifecycle manager 5.0

ibm rational engineering lifecycle manager 1.0

ibm rational engineering lifecycle manager 1.0.0.1

ibm rational engineering lifecycle manager 4.05

ibm rational engineering lifecycle manager

ibm rational engineering lifecycle manager 4.03

ibm rational engineering lifecycle manager 4.04

ibm rational software architect design manager 4.0.5

ibm rational software architect design manager

ibm rational software architect design manager 3.0

ibm rational software architect design manager 3.0.0.1

ibm rational software architect design manager 5.0

ibm rational software architect design manager 4.0.3

ibm rational software architect design manager 4.0.4

ibm rational software architect design manager 4.0.0

ibm rational software architect design manager 4.0.1

ibm rational software architect design manager 4.0.2